Back to cases

Live public case

Opportunistic scan

Last activity Aug 30, 1:36:54 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is strongly consistent with real opportunistic PHP/WordPress web-shell path enumeration against target privatekind. Verified HTTP summaries show rapid GET requests categorized as PHP/WordPress probes from the same source cluster, with distinct path hashes and rejection/redirect outcomes. The available responses include 404s and a 301; these support unsuccessful discovery attempts but, by themselves, do not prove that every request failed to trigger application behavior. No process or flow evidence is cited by this incident, so there is no evidence-grounded basis to claim command execution, outbound activity, persistence, or compromise. The verdict therefore affirms the scanning activity, not successful exploitation.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to a short burst of inbound probe traffic; no confirmed execution, outbound activity, persistence, or compromise is established.
  • The probes tested whether PHP/WordPress web-shell-like paths were exposed, creating discovery risk even though the observed HTTP outcomes were redirects or rejections.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is strongly consistent with real opportunistic PHP/WordPress web-shell path enumeration against target privatekind. Verified HTTP summaries show rapid GET requests categorized as PHP/WordPress probes from the same source cluster, with distinct path hashes and rejection/redirect outcomes. The available responses include 404s and a 301; these support unsuccessful discovery attempts but, by themselves, do not prove that every request failed to trigger application behavior. No process or flow evidence is cited by this incident, so there is no evidence-grounded basis to claim command execution, outbound activity, persistence, or compromise. The verdict therefore affirms the scanning activity, not successful exploitation.